Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Customer Voice Portal Information Disclosure Vulnerability

cisco-sa-cvp-info-dislosure-NZBEwj9V · Medium · Published · Updated

A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device. There are workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cvp-info-dislosure-NZBEwj9V

Workarounds

There is a workaround that addresses this vulnerability.

It is possible to configure certificate-based authentication for the vulnerable interface. This is documented in the Secure JMX Communication between OAMP and Call Server using Mutual Authentication section of the Configuration Guide for Cisco Unified Customer Voice Portal, Release 12.5(1) https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cust_contact/contact_center/customer_voice_portal/cvp_12_5/configuration/guide/ccvp_b_configuration-guide-12-5-1/ccvp_b_configuration-guide-12-5-1_chapter_010001.html?bookSearch=true .

CVEsCVE-2020-3402
Cisco Bug IDsCSCvp98656, CSCvt45220
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified IP Interactive Voice Response (IVR)

Related Products

Product CVE Evidence
Cisco Nexus Dashboard CVE-2020-3402 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2020-3402 Cisco OpenVuln
Cisco Unified IP Interactive Voice Response (IVR) CVE-2020-3402 Cisco OpenVuln
Cisco Unified IP Interactive Voice Response CVE-2020-3402 Cisco OpenVuln